SilverAlbum

This is a convenience translation. The legally binding version is the Polish original. If the two differ, the Polish text prevails.

Privacy Policy

Effective from 27 September 2026

§ 1Who is the controller

  1. The controller of the personal data of users of the SilverAlbum service is Sławomir Mularski, running a business under the name Elektro Joker Sławomir Mularski, Pstrągówka 161a, 38-124 Wiśniowa, Poland, tax identification number (NIP) 8191648933. Contact in personal data matters: bok@silveralbum.art.
  2. Photos uploaded by photographers are a separate matter. With regard to images of persons captured in those photos, the photographer is the controller, and SilverAlbum acts as a processor on the photographer’s instructions. Details in § 12 of the Terms of Service.

§ 2What data we process and why

Data of photographers using the service:

  • Account: first name and surname, e-mail address, password in hashed form — to provide the service (Article 6(1)(b) GDPR).
  • Profile and portfolio: studio name, description, logo, portfolio address — to provide the service.
  • Billing: plan, payment history, invoicing details — to perform the contract and comply with tax obligations (Article 6(1)(b) and (c) GDPR).
  • Technical logs: IP address truncated to its prefix, browser type, request time — to ensure security, on the basis of legitimate interest (Article 6(1)(f) GDPR).

Data of people who write to us or visit SilverAlbum's informational pages:

  • Contact form (help center and panel): name, e-mail address, topic, message, optionally a gallery link, the address of the page the message was sent from and the IP address truncated to its prefix — to answer the request and protect the form against abuse, on the basis of legitimate interest (Article 6(1)(f) GDPR), and for pre-sales questions — to take steps prior to entering into a contract (Article 6(1)(b) GDPR).
  • Analytics (only with consent): visit statistics (Google Analytics 4) and click heatmaps and session recordings with typed text masked (Microsoft Clarity) — to understand how our informational pages are used and improve them, on the basis of your consent (Article 6(1)(a) GDPR). Details in section 6.

Data of people visiting galleries and booking sessions:

  • Photo selection: e-mail address and, optionally, first name, provided voluntarily when marking photos — so that the photographer knows whose selection it is.
  • Session booking: first name and surname, e-mail address, optionally phone number and comments.
  • Gallery activity history: the fact that a gallery was opened, a photo was downloaded (together with the name of the downloaded file) and a selection was submitted — with a truncated IP address and browser identification. The photographer sees these events in the dashboard, to know whether the client has received the material.

In these cases the controller is the photographer who runs the gallery. SilverAlbum processes this data on the photographer’s instructions.

§ 3What we do not do

  1. We do not perform facial recognition or any other biometric processing. Photos are not analysed to establish the identity of persons.
  2. We do not use photos to train machine learning models.
  3. We do not sell personal data or share it with advertisers.
  4. We do not profile users in a way that produces legal effects for them.

§ 4How long we keep data

  1. Account data — for the duration of the contract and 90 days after its termination, in accordance with § 5 of the Terms of Service.
  2. Billing data — for the period required by tax law, as a rule 5 years from the end of the tax year.
  3. Data of persons booking a session — for 24 months from the session date, for the purpose of handling any complaints.
  4. Gallery activity log — for as long as the gallery exists, until it is deleted by the photographer or the account is deleted.
  5. Technical logs — up to 12 months.
  6. Contact form messages — 24 months after the matter is closed.
  7. Analytics data — 14 months in Google Analytics; in Microsoft Clarity according to the service settings, session recordings up to 30 days. Analytics cookies — as listed in section 6 or until consent is withdrawn.

§ 5Who we entrust data to

We use the services of entities that process data on our behalf. They are our sub-processors within the meaning of § 12(8) of the Terms of Service:

  • Cloudflare — file storage (R2 object storage). We store photo data in the European Union region.
  • Hostinger — application server and database.
  • Resend — sending e-mail messages (notifications about bookings, photo selections, expiring galleries).
  • Stripe — payment processing. SilverAlbum does not store card numbers.

If any of these entities processes data outside the European Economic Area, this takes place on the basis of standard contractual clauses approved by the European Commission.

Only with your consent and only on SilverAlbum's informational pages (home page, pricing, guides, help center, legal pages, referral program and the sign-in screen) we use analytics tools:

  • Google Analytics 4 — Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC in the USA on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework. Google Analytics 4 does not store full IP addresses. Advertising signals and Google Signals are disabled.
  • Microsoft Clarity — Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Click heatmaps and session recordings in which text typed into form fields is masked (it does not reach Microsoft). Data may be transferred to Microsoft Corporation in the USA on the basis of the EU-US Data Privacy Framework.

These tools never run in client galleries, portfolios, booking pages or the photographer panel and receive no photos or data from those places. They are therefore not sub-processors of data entrusted to us by photographers.

§ 6Cookies

We do not use cookies for advertising. Analytics only runs with your consent and only on our informational pages — never in client galleries or the photographer panel. Below is the full list of what we actually store.

Strictly necessary — the service does not work without them, so they do not require consent:

  • better-auth.session_token (prefixed with __Secure- over HTTPS) — the logged-in photographer's session; up to 30 days, renewed while using the panel, deleted on sign-out,
  • sg_<gallery id> — gallery access, stored after the correct password is entered so it does not have to be typed for every photo; valid for up to 30 days and carrying only the gallery identifier, the scope of access and the e-mail address provided,
  • sgt_<gallery id> — a random photo-selection key, so that a selection belongs to the browser that started it; up to 12 months,
  • shutter_ref — the referral code stored after arriving via a referral link, so the bonus can be granted at sign-up; 60 days, removed after sign-up,
  • shutter.cookies.v1 (browser local storage, not a cookie) — your cookie choice; until you change it or clear your browser data.

Analytics — set only with your consent and only on informational pages:

  • _ga, _ga_<id> (Google Analytics) — distinguishing visitors and sessions in statistics; up to 2 years,
  • _clck (Microsoft Clarity) — Clarity visitor identifier; 1 year,
  • _clsk (Microsoft Clarity) — joining page views into one session recording; 1 day,
  • MUID (bing.com / clarity.ms domain, Microsoft) — identifier used by Clarity to recognise the browser; up to 1 year.

You can withdraw consent at any time via the “Cookie settings” link in the page footer — the analytics tools then stop and we delete their cookies on our domain. Withdrawal does not affect the lawfulness of processing carried out before it.

§ 7Your rights

You have the right to access your data, to rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interest. You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).

If your photo appears in a gallery run by a photographer, direct any erasure request to the photographer first — they are the controller of that data. You can also write to us, and we will forward the matter and support the photographer in handling it.